CVE-2022-36640

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-36640
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36640.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-36640
Aliases
Withdrawn
2022-09-04T04:38:45Z
Published
2022-09-02T21:15:16Z
Modified
2025-07-29T10:38:32.058359Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

influxData influxDB before v1.8.10 contains no authentication mechanism or controls, allowing unauthenticated attackers to execute arbitrary commands. NOTE: the CVE ID assignment is disputed because the vendor's documentation states "If InfluxDB is being deployed on a publicly accessible endpoint, we strongly recommend authentication be enabled. Otherwise the data will be publicly available to any unauthenticated user. The default settings do NOT enable authentication and authorization.

References

Affected packages

Debian:11 / influxdb

Package

Name
influxdb
Purl
pkg:deb/debian/influxdb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.7~rc0-1
1.6.7~rc0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / influxdb

Package

Name
influxdb
Purl
pkg:deb/debian/influxdb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.7~rc0-1
1.6.7~rc0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / influxdb

Package

Name
influxdb
Purl
pkg:deb/debian/influxdb?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

1.*

1.6.7~rc0-2

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/influxdata/influxdb

Affected ranges

Type
GIT
Repo
https://github.com/influxdata/influxdb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*

v0.0.1
v0.0.2
v0.0.3
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.0.9
v0.1.0
v0.1.1.rc1
v0.1.1.rc3
v0.1.1.rc4
v0.1.1.rc5
v0.1.1.rc6
v0.10.0
v0.10.0-beta1
v0.10.0-beta2
v0.10.0-rc1
v0.10.0-rc2
v0.13.0
v0.13.0-rc1
v0.13.0-rc2
v0.2.0
v0.3.0
v0.3.1
v0.3.2
v0.4.0
v0.4.0.rc1
v0.4.0.rc2
v0.4.0.rc3
v0.4.0.rc4
v0.4.0.rc5
v0.4.0.rc6
v0.4.0.rc7
v0.4.1
v0.4.2
v0.4.3
v0.4.4
v0.5.0
v0.5.0-rc.1
v0.5.0-rc.2
v0.5.0-rc.3
v0.5.0-rc.4
v0.5.0-rc.5
v0.5.0-rc.6
v0.5.1
v0.5.10
v0.5.11
v0.5.12
v0.5.2
v0.5.3
v0.5.4
v0.5.5
v0.5.6
v0.5.7
v0.5.8
v0.5.9
v0.6.0
v0.6.1
v0.6.2
v0.6.3
v0.6.4
v0.6.5
v0.7.0
v0.7.1
v0.7.2
v0.7.3
v0.8.0
v0.8.0-rc.1
v0.8.0-rc.2
v0.8.0-rc.3
v0.8.0-rc.4
v0.8.0-rc.5
v0.8.1
v0.8.2
v0.8.3
v0.8.4
v0.8.4-rc.1
v0.8.5
v0.8.6
v0.8.7
v0.9.0
v0.9.0-rc10
v0.9.0-rc11
v0.9.0-rc12
v0.9.0-rc13
v0.9.0-rc14
v0.9.0-rc15
v0.9.0-rc16
v0.9.0-rc17
v0.9.0-rc18
v0.9.0-rc19
v0.9.0-rc2
v0.9.0-rc20
v0.9.0-rc21
v0.9.0-rc22
v0.9.0-rc23
v0.9.0-rc24
v0.9.0-rc25
v0.9.0-rc26
v0.9.0-rc27
v0.9.0-rc28
v0.9.0-rc29
v0.9.0-rc3
v0.9.0-rc30
v0.9.0-rc31
v0.9.0-rc32
v0.9.0-rc33
v0.9.0-rc4
v0.9.0-rc5
v0.9.0-rc6
v0.9.0-rc7
v0.9.0-rc8
v0.9.0-rc9
v0.9.1-rc1
v0.9.3-rc1
v0.9.4-rc1
v0.9.5-rc1
v0.9.6-rc1

v1.*

v1.0.0
v1.0.0-beta1
v1.0.0-beta2
v1.0.0-beta3
v1.0.0-rc1
v1.0.0-rc2
v1.0.1
v1.0.2
v1.1.0
v1.1.0-rc1
v1.1.0-rc2
v1.2.0
v1.2.0-rc1
v1.2.0-rc2
v1.2.1
v1.2.1-rc1
v1.2.1-rc2
v1.2.1-rc3
v1.2.1-rc4
v1.2.1-rc5
v1.2.2
v1.3.0rc1
v1.4.0rc0
v1.5.0
v1.5.0rc0
v1.5.0rc1
v1.5.0rc2
v1.5.0rc3
v1.5.0rc4
v1.5.0rc5
v1.5.0rc6
v1.6.0rc0
v1.8.0rc0
v1.8.0rc1
v1.8.0rc2
v1.8.0rc3